mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
cb35e1f98e38db4f6eeaef2f9b2bce4151d69d9e
37830
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
cb35e1f98e |
chore(library): update routes, redirects, and naming (#48668)
Our UI Library registry is expanding to include blocks that go beyond UI and in some cases focus purely on back-end. This PR is a precursor to adding more back-end related blocks. This PR includes the `ui-library -> library` rename plus redirects and small UI copy updates. Since this is a rename we'll need to update Vercel configuration. ## Vercel rollout Keep the Library project Root Directory as `apps/ui-library` 1. In the **Library** Vercel project, set: `NEXT_PUBLIC_BASE_PATH=/library` Apply it to Preview and Production, then redeploy the Library project. 2. In the **www** Vercel project, add: `NEXT_PUBLIC_LIBRARY_URL=<current value of NEXT_PUBLIC_UI_LIBRARY_URL>` Apply it to Preview and Production. Keep `NEXT_PUBLIC_UI_LIBRARY_URL` during the migration, then redeploy the www project. 3. Deploy in this order: 1. Library project 2. www project 4. Validate: - `/library` - `/library/docs/nextjs/password-based-auth` - `/ui` redirects to `/library` - `/ui/docs/nextjs/password-based-auth` redirects to `/library/docs/nextjs/password-based-auth` - `/ui/docs/ai-editors-rules/*` still uses its existing Docs redirects No Vercel dashboard redirect rules are needed. Environment-variable changes require a new deployment. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Supabase UI Library has been renamed to **Supabase Library** across navigation, pages, documentation, and resource links. * The Library is now available at `/library`, with updated descriptions covering components, blocks, and developer tools. * **Bug Fixes** * Added permanent redirects from legacy `/ui` URLs to corresponding `/library` paths. * Updated links throughout the site and documentation to prevent broken navigation and references. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
1296a1c745 |
feat(studio): notebook query and mutation hooks (#48907)
## Summary Implements the "notebook query and mutation hooks" step of the notebooks data layer: - `data/content/notebooks/notebook-query.ts` — `getNotebook`/`useNotebookQuery`, wrapping the existing `getContentById` and narrowing to `type: 'notebook'`. - `data/content/notebooks/notebooks-infinite-query.ts` — `useNotebooksInfiniteQuery`, a typed wrapper over `useContentInfiniteQuery` narrowing pages to notebook rows. - `data/content/notebooks/notebook-upsert-mutation.ts` — `createNotebook`/`updateNotebook` + their mutation hooks, PUTting through the existing `upsertContent`. Write-path correctness, worked out while building the mutation hooks: - Cell `id`s are always backend-generated, never client-supplied — a brand-new cell has no `id` at all; an existing cell being kept/edited in an update keeps its real id so the backend can diff it against the previous version. `notebook-schema.ts` gains `writableCellSchema`/`writableNotebookSchema` (ids optional per cell) and `WritableCell`/`WritableNotebook` types, derived from `z.infer` of those schemas rather than hand-duplicated, with only the `sql` field re-branded per cell type via a small distributive conditional type. - Cell SQL at this write boundary must already be `SafeSqlFragment`/`SafeLogSqlFragment` (proven user-authored at a save/run event handler), not `unchecked_sql` — matching the `safe-sql-execution` skill's provenance model. - `content-remap.ts`'s notebook `unmapSqlContentField` branch is simplified to a passthrough: notebook writes only ever arrive already wire-shaped via `createNotebook`/`updateNotebook`, so there's nothing left to unmap. Note: this was originally stacked on `feature/notebooks-types-convergence`, but that branch merged into `master` (#48905) while this PR was in progress, so it's rebased directly onto `master` now. ## Test plan - [x] `pnpm --filter studio run typecheck` passes - [x] `pnpm --filter studio exec vitest run data/content/notebooks data/content/content-remap.test.ts` — 38/38 passing - [x] `pnpm --filter studio exec eslint` clean on all touched files <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added notebook listing with pagination, filtering, sorting, and project-specific queries. * Added notebook retrieval for viewing individual notebooks. * Added notebook creation and editing with automatic content refresh. * Added support for preserving cell IDs and safely handling SQL content. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0111aa371b |
ref(studio): converge notebook UI types with canonical content schema (#48905)
## Summary - Joshen's `state/notebooks/types.ts` (Explorer/notebook editor UI) redefined its own `TimeRange`, cell union, and `NotebookContent` shapes, duplicating the canonical schema from `data/content/notebooks/notebook-schema.ts` (#48813, #48815). - Points `Notebook.content` and `notebooksState.updateCells` at the canonical `Notebooks.Content` / `Notebooks.Cell` types (via `@/types`) instead, and fixes the handful of call sites that constructed notebook content by hand to match the real wire shape: `schema_version: 1` (not `'1.0'`) and `_tag`-discriminated cells (e.g. `{ _tag: 'markdown_cell', id, text }` instead of `{ type: 'markdown', content }`). - No behavioral changes — Joshen's state management, editor component, and hooks are untouched aside from the type-level fixes needed to compile against the canonical schema. ## Test plan - [x] `pnpm exec tsc --noEmit` — no new errors - [x] `pnpm exec vitest run state/notebooks/notebooks-state.test.ts components/interfaces/Explorer/__tests__/NotebookEditor.test.tsx` — 8/8 passing - [x] `pnpm exec eslint` on changed files — clean - [x] `pnpm exec prettier --check` on changed files — clean <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Updated notebook content handling to use the current schema version format. * Improved compatibility for markdown cells, including their identifiers and text. * Standardized notebook content and cell updates for more consistent behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b04d14856a |
Resolve AI opt-in and tracing settings server-side (#48855)
The AI endpoints resolved organization and project settings independently and applied them together without confirming they belonged to the same pairing. Consolidates both into a single `getAIDetails` that reconciles them and falls back to the most restrictive posture when unconfirmed, and applies the HIPAA sensitivity gate to the opt-in level, which previously only existed on the client. Fixes FE-4110 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Consolidated AI access details across organization and project settings. - AI functionality now validates project ownership and disables access for mismatched or HIPAA-sensitive projects. - AI responses include plan, region, opt-in status, sensitivity, authorization, and advanced model access information. - **Bug Fixes** - Improved fail-closed behavior when project or organization data is missing or inconsistent. - Updated AI generation, feedback, rate, and policy flows to consistently apply consolidated access settings. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
957e9fec67 |
feat(studio): notebook content at the API boundary (#48815)
## Summary Stacked on #48813 (1.2: notebook content schema). Part of [FE-4109](https://linear.app/supabase/issue/FE-4109/notebooks-data-model) — see that issue for the rest of the notebooks data-model stack. - Teach `content-remap.ts`'s wire↔domain dispatcher about the `notebook` content type, branding each cell's `sql` per `_tag` via the notebook schemas added in 1.2 (parses through `notebookDomainSchema` on the way in, unbrands per cell on the way out). - Add `{ type: 'notebook'; content: Notebooks.Content }` to the `Content` union in `content-query.ts`, plus a `ContentOfType<T>` helper for narrowing it. - Fix the resulting narrowing fallout at call sites that assumed `Content` only ever meant `sql`/`report`/`log_sql`: two generated-query-param casts, and four report/logs call sites now narrowed via `ContentOfType<'report'>` / `ContentOfType<'log_sql'>`. ## Test plan - [x] `pnpm --filter studio vitest run data/content/` — 35 tests pass, including new notebook coverage in `content-remap.test.ts` (per-cell brand separation, missing-field throw, remap↔unmap round-trip) - [x] `pnpm typecheck` — clean (pre-existing unrelated `ui-patterns` error aside) - [x] `pnpm --filter studio lint` — no new warnings/errors on changed files - [x] `pnpm format` — clean --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
c3742ba07f | ref(pipelines): Align handling of credentials (#48896) | ||
|
|
6594f412f9 |
docs: add Warp as a supported MCP client (#48838)
Adds [Warp](https://www.warp.dev/) as a supported client in the Supabase MCP docs. Because [Warp speaks the native remote (Streamable HTTP) transport](https://docs.warp.dev/agents/capabilities/mcp/), the standard config connects to the hosted server directly, no `mcp-remote` proxy needed: ```json { "mcpServers": { "supabase": { "url": "https://mcp.supabase.com/mcp" } } } ``` The MCP client list is data-driven, so this single addition surfaces in the docs MCP panel, the generated markdown, and Studio's Connect panel. Concretely: registers the `warp` client (config file `~/.warp/.mcp.json`, docs link) under the IDE group, adds setup instructions (auto-load + Settings → AI → MCP Servers, automatic OAuth), and adds the official Warp logo in light and dark variants. ## What is Warp? Warp is an agentic development environment built from the terminal: a Rust-based, GPU-accelerated app that runs coding agents (Claude Code, Codex, Gemini) directly in the terminal. It has first-class MCP support with native remote (Streamable HTTP / SSE) transport and automatic OAuth (no PAT required). ## Why add support for the Supabase MCP server? Warp is a mainstream, widely-adopted client ([warpdotdev/warp](https://github.com/warpdotdev/warp) has 64k+ ⭐ on GitHub) that natively supports MCP. Documenting it lets Warp users connect the hosted Supabase MCP server with a copy-paste config, matching the coverage we already provide for Cursor, VS Code, Windsurf, and others. ## How to test 1. Run the docs app (`pnpm dev:docs`) and open the MCP guide (`apps/docs/content/guides/ai-tools/mcp.mdx`). Warp appears under **IDE** with its logo (verify both light and dark themes) and the config snippet. 2. In Warp, add the shown config to `~/.warp/.mcp.json` (or **Settings → Agents → MCP Servers → + Add**). Warp auto-spawns the `supabase` server. 4. Click **Start** on the `supabase` server → complete the Supabase OAuth in the browser → the Supabase tools load. <img width="859" height="606" alt="image" src="https://github.com/user-attachments/assets/8c931ded-4ffe-4495-b4c8-183f93be812a" /> Verified end-to-end on Warp v0.2026.07.29 (macOS): the config auto-loads and connects over Warp's native remote transport, and the OAuth flow completes without a PAT. Refs [AI-1031](https://linear.app/supabase/issue/AI-1031/docs-add-warp-as-a-supported-mcp-client) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added Warp as a supported MCP client. * Added setup guidance for connecting remote MCP servers in Warp, including OAuth authentication and secure credential storage. * Added light and dark Warp icons to the client selection interface. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|
|
ae9042ceb4 |
feat(docs): scoped pat update (#48802)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Updates docs around scoped PAT's. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified that temporary database access uses a Personal Access Token as the Postgres role password. * Updated API documentation to explain that Personal Access Tokens support custom expiration rather than being described as long-lived. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5b68af1720 |
feat(studio): role-aware access feedback in scoped token creation (#48858)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Remaining bits of #48714 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added role-aware access checks throughout scoped token creation. * Organization selectors now disable project-only organizations and recommend project-scoped tokens when appropriate. * Review screens highlight missing capabilities and permissions exceeding your current role. * Permission rows display indicators when access exceeds your role. * Added resource keys, labels, and summaries to improve token review clarity. * **Documentation** * Updated permission guidance with links to access-control documentation. * **Bug Fixes** * Corrected project selector behavior when no organization is selected. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6c414e363d |
Initialize notebook editor page (#48842)
## Context More groundwork for the Explorer - this PR initializes the Notebook editor page which you can access with the "New notebook" CTA As usual nothing functional just yet, but this PR also addresses some UI functionality - Creating more than 1 notebook will open multiple tabs (it wasn't previously) - Swapping between notebooks will update the URL (wasn't previously as well) Will probably start looking into the cells next, starting with MarkdownCell followed by QueryCell <img width="1390" height="894" alt="image" src="https://github.com/user-attachments/assets/a467cdb4-f99f-43db-8106-c15c26c1bfbf" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added notebook creation actions from the Explorer home and navigation areas. * Introduced a full notebook editor with title editing, rename support, and Analyze, Run, and Save controls. * Added options to create query or Markdown cells in empty notebooks. * Notebook tabs now open the corresponding notebook in the project Explorer. * **Bug Fixes** * Improved Explorer layout sizing and notebook tab navigation behavior. * Improved notebook tab labels and editing behavior, including cancellation with Escape and submission with Enter or blur. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
777c02c205 |
test(docs): scan changed pages for WCAG 2.1 A/AA in warn mode (#48727)
Closes DOCS-1233 ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Test coverage. The docs accessibility check now covers the full WCAG 2.1 A/AA rule set instead of two rules. **Note:** This PR tests _only_ the main article of changed pages (meaning, the content itself). A follow-up Linear issue is to address scanning the pieces outside of that: header, navigation, and interactive elements. ## What is the current behavior? The `@a11y` test in `e2e/docs` runs two axe rules against each in-scope page, `heading-order` and `page-has-heading-one`. Both already pass everywhere, so the check only guards a result we have. Nothing else in WCAG A/AA is checked. ## What is the new behavior? The same test runs the full WCAG 2.1 A/AA rule set. - **Existing debt does not block PRs.** Only the two heading rules fail. Everything else reports. - **The check stays fast.** It scans the article only and skips nine rules that cannot fire there. Scan time drops from 2405ms to 981ms. - **Findings belong to us.** Legacy mode excludes cross-origin frames. YouTube embeds were counting against us, 11 of 15 violations on one page. - **A pass carries meaning.** A 404 reports as a load failure, not an a11y bug. A page scanned before it hydrates warns instead of quietly reporting clean. ## How the findings appear The test is named `has no blocking accessibility violations`, so a failure listed by CI is always something to fix. It is not named for the full rule set, because a green check would then claim more than the check verifies. | | Rules | Where you see it | | --- | --- | --- | | Blocking | `heading-order`, `page-has-heading-one` | Test failure, so the runner reports it on the PR | | Reported | Everything else in WCAG A/AA | `::warning` annotation on the run | An annotation looks like this, on a run that still passes: ``` ::warning title=Accessibility::/docs/guides/database/functions has 1 non-blocking accessibility finding(s): frame-title (4) ``` The full axe result for each page is attached to the report as `axe-results.json`. ## Matching the Studio ratchet This follows the ESLint ratchet in `apps/studio`. That pattern warns on pre-existing debt rather than blocking on it, surfaces findings as annotations rather than PR comments, and promotes a rule to an error once its violations reach zero. The mechanism here is `ENFORCED_RULES` in `utils/axe-helpers.ts`. The two heading rules are on it because the heading-hierarchy work drove them to zero site-wide. The intent is to migrate rules into that list one at a time. Pick a rule, fix its violations, then move it into `ENFORCED_RULES` so it cannot come back. An exhaustive scan of the site groups the current backlog by root cause to sequence that work, and two fixes cover 99.1% of it. Studio keeps per-file baseline counts, which this does not. A whole-rule list is coarser, and it works here because docs violations reach zero across the site rather than per file. ## Manual testing Install the browser once, then run each step from the repo root. Every command scans production, so you do not need a local docs server. ```bash pnpm -C e2e/docs exec playwright install chromium ``` 1. Confirm a reported finding does not fail the check. ```bash DOCS_E2E_PAGE_PATHS=/docs/guides/database/functions PLAYWRIGHT_BASE_URL=https://supabase.com pnpm e2e:docs:a11y ``` Expect `1 passed`, and the `::warning` annotation above in the output. 2. Confirm the scan finds that violation. Same page, now failing on every rule. ```bash A11Y_ENFORCE_ALL=1 DOCS_E2E_PAGE_PATHS=/docs/guides/database/functions PLAYWRIGHT_BASE_URL=https://supabase.com pnpm e2e:docs:a11y ``` Expect `1 failed`, reporting `frame-title (serious, 4 node(s))`. Steps 1 and 2 together are the point of this PR. 3. Confirm the skipped rules stay skipped. ```bash A11Y_ENFORCE_ALL=1 DOCS_E2E_PAGE_PATHS=/docs/guides/getting-started/quickstarts/nextjs PLAYWRIGHT_BASE_URL=https://supabase.com pnpm e2e:docs:a11y ``` Expect `button-name (critical, 2 node(s))` and `label (critical, 2 node(s))`, and no `color-contrast`. 4. Confirm a page that does not load reports a load failure. ```bash DOCS_E2E_PAGE_PATHS=/docs/guides/does-not-exist-xyz PLAYWRIGHT_BASE_URL=https://supabase.com pnpm e2e:docs:a11y ``` Expect `Expected a successful response for /docs/guides/does-not-exist-xyz, got 404`, and no axe assertion. 5. Confirm the link checker still passes alongside the a11y test. ```bash DOCS_E2E_PAGE_PATHS=/docs/guides/auth/passwords PLAYWRIGHT_BASE_URL=https://supabase.com pnpm e2e:docs ``` Expect `3 passed`. ## Known gaps - `/docs/reference/*` is not scanned. Those routes render client-side into tens of thousands of elements, where axe exceeds its timeout and results depend on whether the scan caught the page mid-render. - Shared chrome is outside the article scope, so nav, sidebar, footer, menus, and drawers are not covered. - axe catches roughly 30-40% of WCAG issues. Keyboard navigation, focus management, and screen reader behavior still need manual testing. --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
18c26bf933 |
docs(auth): clarify audit logs storage options and configuration (#48852)
## Summary - Clarify that external log storage is the default - Explain that Postgres database storage is optional - Fix grammar and typos - Improve admonition messaging to be more actionable - Simplify toggle step wording for clarity Slack thread with team-auth: https://supabase.slack.com/archives/C022071RB2L/p1785945149999009 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified that audit logs are stored in external log storage by default. * Documented optional database storage in `auth.audit_log_entries`. * Added instructions for enabling or disabling database storage with the “Write audit logs to the database” toggle. * Noted that enabling database storage incurs additional database storage costs. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
124ff77ad0 |
feat(studio): warn that scoped tokens don't support the MCP server (#48849)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Scoped PATs are blocked from the Supabase MCP server until AI-1025 ships FGA guard support, so surface that on the scoped review step (with a link back into legacy mode) and on the view-token sheet, sharing one warning module for easy removal. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a clear notice explaining that scoped access tokens aren’t supported by the Supabase MCP server. * Added an option to create a legacy token when applicable. * Displayed the MCP compatibility notice in token review and access views. * **UI Improvements** * Organization selectors now display their associated icons. * Standardized MCP guidance across token-related screens for a more consistent experience. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
33482bdc88 |
feat(studio): lifecycle and role-aware scoped token view sheet (#48848)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Extracts the token view sheet slice of #48742
(w3b6x9/scoped-pat-access-feedback, commit
|
||
|
|
86854671e9 |
feat(www): add Open Authorization Integration Addendum (#48804)
<!-- ccr-slack-attribution --> _Requested by **Nicole Kramer** · [Slack thread](https://supabase.slack.com/archives/C0161K73J1J/p1786027145751449)_ ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Feature — a new legal page on the marketing site (`apps/www`). ## What is the current behavior? **Before:** the Program Addenda page at `/legal/partner-resources/program-addenda` lists exactly one addendum, the Integration Partner Addendum. There is no published Open Authorization (OAuth) addendum anywhere on the site. ## What is the new behavior? **After:** the Program Addenda page also lists the **Open Authorization Integration Addendum**, linking to a new page at `/legal/partner-resources/program-addenda/oauth-partner-addendum`. Formatting, breadcrumbs, version selector, and listing badge all match the existing Integration Partner Addendum. **How:** three files. - `apps/www/data/legal/partner-resources/oauth-partner-addendum/20260806-v1.mdx` — the addendum text, formatted to match `integration-partner-addendum/20260615-v1.1.mdx` (escaped section-number periods, `####` run-in headings for the lettered subsections, italic `_Label_` run-in labels for the enumerated data-protection clauses, explicit `[url](url)` links). - `apps/www/pages/legal/partner-resources/program-addenda/oauth-partner-addendum.tsx` — the page, mirroring `integration-partner-addendum.tsx` with a single-version `versions` array. - `apps/www/lib/addenda.ts` — adds a small `TITLE_OVERRIDES` map. The listing derives titles by capitalizing slug words, which turns `oauth-partner-addendum` into "Oauth Partner Addendum"; the override makes the listing link read the same as the page's `h1`. No other wiring was needed: the addenda listing is generated from the directory, so there is no hub entry, redirect, rewrite, sitemap entry, or `noindex` rule to add. ## Additional context Two things for the requester to confirm: - **The effective date is an assumption.** The addendum document itself contains no date. The listing and version label derive the effective date from the `YYYYMMDD` filename prefix, so this file is dated **August 6, 2026**, taken from the source document's own filename (`2026.08.06 - Supabase-OAuthAddendum-ONLINE.docx`). To change it, rename the file — no code change required. - **The legal text is a verbatim transcription.** Source wording, capitalization, and punctuation are preserved exactly as drafted, including anything that reads like a typo. Only markup was added; the plain text was diffed against the transcription and is character-identical. Please review the wording itself rather than assuming it was copy-edited. One wording choice that was not in the source document: the page subheader, "An addendum to the Master Partner Program Agreement governing OAuth integrations." It mirrors the one-line subheader style of the existing addendum page and is easy to reword. ## Also fixed here: a literal `(c)` rendered as `©` in legal headings While formatting the new addendum we hit a rendering bug that turned out to be **already live on supabase.com**, not new to this branch. The heading font, **Manrope**, ships a default-on standard `liga` feature that maps the glyph sequence `parenleft c parenright` to the copyright glyph. So a literal `(c)` anywhere inside an `h2`–`h6` on the marketing site paints as `©`. Body copy is unaffected because it uses Inter, whose subset has no such ligature — which is why this only ever shows up in headings. This branch adds a `legal-prose` utility (`font-variant-ligatures: no-common-ligatures`) in `apps/www/styles/globals.css` and applies it to two pages: - the new **Open Authorization Integration Addendum** page (heading `#### (c) Security.`), and - the **Master Partner Program Agreement** page, where the `#### (b) Such indemnity …` heading in section 17.1 contains `… ; or (c) replace the Covered Materials …` about 600 characters into the line. That page was **already published**, and rendered "or © replace the Covered Materials" in production. The MPPA change is one word — `className="prose"` → `className="prose legal-prose"`. **No legal text was modified**: no HTML entities, no zero-width characters, no rewording, no re-hyphenation. The DOM still holds `U+0028 U+0063 U+0029`; only the font's shaping is suppressed. Verified in Chromium against the real heading text and the same two font subsets `next/font` serves: the `(c)` run measures **15.36px** before the fix (a single `©` glyph) and **22.05px** after (three literal glyphs), against a 23.30px control for the `(b)` in the same heading. All 17 `.mdx` files under `apps/www/data/legal/` were swept for `(c)` and the other Manrope `liga` input sequences (`--`, `->`, `<-`, `(>)`, `<3`) on heading lines. The only two hits are the two pages fixed above; nothing else needs the utility today. (Headings do contain `ff`/`fi`/`fl`/`tt` — those ligatures are ordinary typography and are intentionally left alone.) **For future legal pages:** because the cause is the heading font's default ligature rather than anything about these documents, any new legal page whose source has `(c)` in a heading will need `legal-prose` on its prose container too. **One side effect worth flagging:** `no-common-ligatures` is blunt, so on those two pages it also suppresses the ordinary `fi`, `ff` and `tt` ligatures — a sweep of the legal `.mdx` files counts 107 such occurrences in headings (`fi` 83, `ff` 21, `tt` 3, `fl` 0), so the note above about leaving them alone holds for the rest of the site rather than for these two pages. That is a deliberate trade-off: correctness of the legal text beats typographic polish on two addendum pages. A narrower alternative exists — `font-feature-settings: "liga" 0` scoped to just the offending ligature, or overriding only the `parenleft_c_parenright` substitution — but it is more fragile and more subset-specific, so push back here if you would rather have that instead. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01VtcJJGqw5jL1ESwhs8DGCu --------- Co-authored-by: Claude <noreply@anthropic.com>v1.26.08 |
||
|
|
3a98b0c818 |
feat(studio): add legacy token mode to scoped pat creation flow (#48844)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Replaces the scoped form's inline account-level access mode with a proper legacy-token escape hatch: "Create legacy token" switches the sheet to the classic form (name + expiry only) and creates through the legacy endpoint, skipping the two-step review. Mirrors the mode-switch links in both directions and restores the "Generate token for experimental API" split-button dropdown, extracted into a shared ExperimentalTokenDropdown. Ported from origin/w3b6x9/scoped-pat-ui-rework, excluding its expiry handling (shipped in #48811) and MCP-unsupported warnings (follow-up PR). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for creating classic account-wide access tokens alongside scoped tokens. * Added an experimental token dropdown for quick token creation. * Added links to switch between scoped and legacy token creation flows. * Classic token creation now provides dedicated warnings and simplified access settings. * **Improvements** * Updated token access messaging, descriptions, and labels for clarity. * **Tests** * Expanded coverage for token creation, navigation, validation, and clipboard behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
2e633a3fbe | Add blog post: Supabase is now a connector on Perplexity Computer (#48776) | ||
|
|
e8f5120dc5 |
feat(studio): enforce expiry scoped pat (#48811)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES Waiting on #48809 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added custom access-token expiration date limits, allowing dates from today through one year ahead. * Date pickers now enforce configured minimum and maximum date boundaries. * **Updates** * Removed the option to create non-expiring access tokens. * Expiration is now required when creating classic access tokens. * Improved form reset behavior and expiry tracking. * **Tests** * Added validation coverage for required, valid, and out-of-range custom expiration dates. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Wen Bo Xie <wenbox323@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
f8206a5f81 |
fix(studio): model scoped pat permissions as OR-of-AND alternatives - smaller version (#48809)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Breaking down #48635 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Scoped access tokens now support alternative permission requirements, enabling more precise access for APIs and tools. - Added clearer role and resource access evaluation, including project-specific permissions and partial read access. - Access reviews now identify unavailable or excessive permissions and group inaccessible resources for easier resolution. - **Bug Fixes** - Improved handling of legacy, incomplete, or invalid permission data with safer fallback behavior. - Corrected access filtering for MCP tools and API capabilities. - **Documentation** - Updated access-review wording to clarify the relationship between scopes and related MCP tools. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Wen Bo Xie <wenbox323@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
6c0439ace8 |
fix(ui): opaque default button hover fills (#48837)
## What kind of change does this PR introduce? Bug fix for translucent default Button (and related control) fills that show through stacked content on hover. Resolves [DEPR-636](https://linear.app/supabase/issue/DEPR-636/report-snippet-cell-expand-button-becomes-transparent-on-hover). ## What is the current behavior? Default `Button` hover uses `bg-selection`, and dark-mode rest uses `bg-muted`. After the colour system migration those legacy aliases point at translucent `--accent` / `--muted`, so hover punches through whatever sits behind the button (SQL Editor / Reports cell expand, sticky columns, skip-to-content, etc.). | Before: Light | Before: Dark | | --- | --- | | <img width="491" height="75" alt="CleanShot 2026-08-03 at 09 12 26@2x" src="https://github.com/user-attachments/assets/20e33ba9-74c5-47eb-aced-ac932a0059fa" /> | <img width="205" height="54" alt="21257" src="https://github.com/user-attachments/assets/a2c9f092-18a7-4a4d-a49b-6e019e50895f" /> | ## What is the new behavior? Default Button, Select, MultiSelect, and the CommandMenu trigger use opaque elevation tokens (`bg-background dark:bg-card`, `hover:bg-popover`). SkipToContent drops its opaque-plate workaround. No global `compat.css` alias remaps. | After: Light | After: Dark | | --- | --- | | <img width="466" height="110" alt="CleanShot 2026-08-07 at 16 09 59@2x" src="https://github.com/user-attachments/assets/6410cb58-b37c-427f-a0ff-7b223a7f3f51" /> | <img width="474" height="132" alt="CleanShot 2026-08-07 at 16 08 53@2x" src="https://github.com/user-attachments/assets/575c56d1-8ee5-4eb5-8f08-e4b5af8520f0" /> | ## Additional context - Overlay tokens (`--muted` / `--accent` / `--tertiary`) stay intentional for washes on solid surfaces. Controls that can sit over content should use solid elevation tokens (`card` / `popover`) instead. - Same root cause as the workarounds in #47996 and #48314. - The “View full cell content” control lives in SQL Editor results / Report `QueryBlock` (`ResultCell`), not Table Editor. It only renders when the value is an object/array, contains a newline, or is longer than 60 characters, and it stays `opacity-0` until you hover the cell. ## To test Short path in Studio (light and dark): 1. **Expand button over cell text (clearest repro)** – SQL Editor, run: ```sql select repeat('x', 80) as name; ``` Hover the result cell. The expand control should appear over the text; hover the button itself and confirm the fill is solid (no `x`s showing through). Same control is what Report snippets use. 2. **Any default Button** – Top nav **Connect** (or any bordered default button). Hover: solid fill. 3. **Select** – Project picker or a Settings form select. Trigger hover / open fill stays opaque. 4. **Command menu trigger** – Hover the header search / Cmd-K control; match default Button. 5. **Skip to content** – Tab once on Studio. Skip link hover stays solid over the page behind it. 6. **Editor tabs regression** – SQL / Table Editor tab strip should still look grey in light mode (not washed white). |
||
|
|
9ab06ef9c3 |
fix(ui): restore normal alert text wrapping (#48840)
## What kind of change does this PR introduce? UI bug fix. ## What is the current behavior? `AlertDescription` applies balanced or pretty text wrapping by default. Alert and Admonition copy can redistribute words across lines and leave unnatural ragged edges. ## What is the new behavior? `AlertDescription` uses normal text wrapping by default. Consumers can still opt into balanced wrapping through `className`. | Before | After | | --- | --- | | <img width="1484" height="216" alt="34098" src="https://github.com/user-attachments/assets/6ae828f1-d88d-4c25-af79-fc64388558f3" /> | <img width="1274" height="264" alt="CleanShot 2026-08-07 at 17 18 52@2x" src="https://github.com/user-attachments/assets/bb437bff-206f-4bb7-b5e6-650d5f08f839" /> | # To test Use the Docs and Design System preview deployments: - [Self-hosted Functions](https://supabase.com/docs/guides/self-hosting/self-hosted-functions#using-an-env-file-recommended): check the caution under **Using an env file (recommended)**. The text should fill each line naturally. - [Configure Reverse Proxy and HTTPS](https://supabase.com/docs/guides/self-hosting/self-hosted-proxy-https#set-up-https): check the three titled notes under **Set up HTTPS**, then the caution under **Self-signed certificates (development only)**. - [Design System Admonition examples](https://supabase.com/design-system/docs/fragments/admonition): scan the description-only, titled, and rich-content examples at desktop and a narrow width. Spacing should be unchanged. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved alert description text wrapping for more consistent display across screen sizes. * Preserved support for custom text-balancing styles. * **Tests** * Added coverage verifying alert description attributes, default styling, and consumer-supplied text-balancing classes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
0b97e37ccf |
feat: notebook content schema (#48813)
Related to FE-4109. ## Summary - **API codegen workaround**: Platform API's `notebook` content type hasn't shipped to the OpenAPI spec yet, so `pnpm api:codegen` can't be run. Locally widened `ContentBase.type` to include `'notebook'` (marked with TODO for removal once spec publishes). - **Notebook schema & type system**: Introduced Zod schemas mirroring RFC-defined notebook shape (`schema_version: 1, cells: Cell[]`). Maintains wire/domain boundary (cell `sql` → `unchecked_sql` branded for security). Agent-writable schema for `create_notebook` tool omits cell IDs (backend-generated); future update operations will require them. All TypeScript types are `z.infer`'d from schemas (no hand-written parallel interfaces). - **IsoDateTimeString moved**: Extracted ISO datetime validator from `querySource.ts` to `lib/iso-datetime.ts` (data layer shouldn't import from components layer). Needed by notebook `time_range` fields. ## Test plan - [x] Unit tests: `notebook-schema.test.ts` (9 tests), `iso-datetime.test.ts` (3 tests), `querySource.test.ts` updated and passing (26 tests) - [x] Typecheck: no new errors - [x] Prettier: formatting clean <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added support for validating and processing notebook content, including markdown, database, log cells, time ranges, and chart configurations. - Added compatibility for notebook content types in content handling. - Added reliable ISO date-time validation for notebook data and related features. - **Tests** - Expanded coverage for valid and invalid notebook structures, cell requirements, time ranges, chart settings, and date-time values. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
a515f3d81f |
fix(ui): remove extra spacing before custom reports section (#48796)
Fixes FE-4107. ## What is the current behavior? The Observability sidebar had unnecessary spacing below the Product navigation. - Extra whitespace below the last Product menu item (`Realtime`). ## What is the new behavior? Removes the global flex gap and applies spacing explicitly to the Custom Reports section. - Product navigation ends cleanly at the divider. - Spacing before the Custom Reports section is intentional and consistent. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Improved spacing and alignment in the observability menu. * Added vertical separation around the custom reports section for a cleaner layout. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a71636f5a0 |
feat(marketing): add hint text below Go page form labels (#48824)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Small feature addition to `packages/marketing` (Go page form schema/renderer), plus a copy/layout change on `/go/select-2026/partner-day`. Supersedes #48821 (closed), which is folded in here. ## What is the current behavior? Go page form fields only support a `description` string rendered *below the input*. There's no way to put a short note directly under a field's label, above the input — so the Partner Day RSVP's "attending" question crammed "(your Partner Day invite covers it)" into the question text itself. ## What is the new behavior? - Adds an optional `hint` string to the Go page form field schema (`packages/marketing/src/go/schemas.ts`), rendered as small italic text directly beneath the label, above the input (`packages/marketing/src/forms/MarketingForm.tsx`). - Updates the Partner Day RSVP's "attending" field to use it: the question is now "Would you like to attend Supabase Select on October 2?" with "Your Partner Day invite covers it" as a separate grey/italic hint line underneath. - No other fields set `hint`, so this is backward compatible — verified `vip-experience`'s identical select field (no `hint` set) renders unchanged. ## Additional context - Verified locally in the browser: the new hint renders correctly on Partner Day, and other `_go` pages with form fields are unaffected. - `prettier --check` and `tsc --noEmit` both pass on the changed files. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added optional hint text beneath form field labels, displayed in smaller italic text. * Updated the Select RSVP question to clearly distinguish the attendance prompt from invite coverage details. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
3a383c87c7 |
Initialize notebooks store (#48801)
## Context More groundwork for the Explorer - this one's focused on initializing the valtio store for managing notebooks Store architecture will follow closely with the existing sql-editor-store No data persistence yet, but can test creating a new notebook <img width="195" height="143" alt="image" src="https://github.com/user-attachments/assets/8656fb5b-3a8e-4f71-b2ce-d2f34ca9b552" /> Which should open a placeholder page <img width="1387" height="527" alt="image" src="https://github.com/user-attachments/assets/4a81b1ae-a740-40e6-9d33-29fa4f83b541" /> Closing the notebook brings you back to the explorer home page <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for creating and opening project notebooks from the Explorer. * Added notebook tabs alongside existing entity and SQL tabs. * Added notebook management, including loading, renaming, removing, editing cells, and tracking unsaved changes. * Added support for SQL, logs, and Markdown notebook cells. * Added dedicated notebook routes and an initial notebook editor view. * Added notebook icons throughout the Explorer interface. * **Documentation** * Documented session-scoped notebook state for query results and row limits. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
91a394fc83 |
Use white wordmark for QA.tech primary logo (#48827)
Follow-up to #48798. The primary `logo` was a black app-icon-badge (square background), inconsistent with other customer logos (transparent wordmark/mark, e.g. Brevo). Per explicit direction, this swaps in the same white-on-transparent wordmark already used for `logo_inverse`. **Known tradeoff:** the primary `logo` renders on the site's light-mode background, so this white wordmark will be invisible there. This was confirmed and explicitly accepted rather than left as an oversight. Co-authored-by: Wendie Cheung <wendie.cheung@supabase.io> |
||
|
|
df35577adc |
fix titleless Admonition alignment (#48784)
## What kind of change does this PR introduce? UI bug fix. ## What is the current behavior? Titleless Admonitions using the `description` prop place their compact body text slightly too high beside the icon. Admonition bodies also inherit a 2px bottom margin from `AlertDescription`, making the vertical spacing subtly uneven. ## What is the new behavior? Titleless `description` content receives a small optical offset, centring a one-line description beside the icon. Rich MDX children retain their natural top alignment because Docs prose uses a taller line height. Admonition bodies also remove the inherited 2px bottom margin, balancing the surrounding space without changing the shared `AlertDescription` primitive. | Before | After | | --- | --- | | <img width="1856" height="856" alt="CleanShot 2026-08-05 at 17 52 34@2x" src="https://github.com/user-attachments/assets/5f8fb726-692a-4a63-ab37-8fe87f37edd6" /> | <img width="1676" height="850" alt="CleanShot 2026-08-06 at 12 05 18@2x" src="https://github.com/user-attachments/assets/9d9126fe-50ef-422c-b387-7a45550e73dd" /> | |_Note the imbalanced space under the text_ | _Note how the text is balanced vertically to the icon_ | ## To test - [Design System: Admonition](https://design-system-git-dnywh-fix-titleless-admonitio-db462e-supabase.vercel.app/design-system/docs/fragments/admonition): the description-only reference example, at desktop and mobile widths. - [Studio: Project Settings > Dashboard](https://studio-staging-git-dnywh-fix-titleless-admoniti-908cb8-supabase.vercel.app/dashboard/project/_/settings/dashboard): the Dashboard preferences notice. The dashboardPreferences feature flag must be enabled. - [Docs: Local Development & CLI](https://docs-git-dnywh-fix-titleless-admonition-alignment-supabase.vercel.app/docs/guides/local-development): the titleless container-runtime callout near the top of the page. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved admonition spacing for descriptions and MDX content. * Removed unintended bottom spacing within admonition bodies. * Adjusted vertical spacing for untitled admonitions while preserving titled content layout. * **Tests** * Added coverage for paragraph spacing, wrapper structure, and title-specific styling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
5944fe66f0 |
fix inconsistent product menu dividers (#48787)
## What kind of change does this PR introduce? Bug fix. ## What is the current behavior? Product menu section dividers use the stronger `border-overlay` colour, while the product heading divider uses `border-default`. ## What is the new behavior? Product menu section dividers use the same `border-default` token as the product heading divider in light and dark mode. | Before | After | | --- | --- | | <img width="636" height="1378" alt="CleanShot 2026-08-06 at 15 56 15@2x" src="https://github.com/user-attachments/assets/1628bef1-47c3-4f66-95a8-51b148784cac" /> | <img width="636" height="1378" alt="CleanShot 2026-08-06 at 15 55 55@2x" src="https://github.com/user-attachments/assets/82520caf-0f93-4e0e-951a-c87c9e9e8339" /> | | _Harsh borders between sections_ | _Borders match top one_ | <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Updated the product menu group separator to use the standard border color for a more consistent appearance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6ac0316738 | Add QA.tech customer case study (#48798) | ||
|
|
66a4a0b32d | fix(docs): realtime deletes can be surfaced and filtered (#48785) | ||
|
|
2a3025df25 |
feat(studio): role inference core for scoped pat (#48805)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Logic-only extraction from #48742. Scoped PATs are enforced server-side as the intersection of the token's granted scopes and the owner's live role, re-checked on every request. This lands the pure inference layer that will power advisory (never blocking) UI feedback; no UI consumes it yet. - FGA_SCOPE_MINIMUM_ROLE: all 83 permission scopes transcribed from the OpenFGA model's role unions, mapped to the lowest base role that holds them. A drift-guard test pins the key set to the scope ids published in @supabase/shared-types, so upstream additions fail CI here with re-transcription instructions. - estimateRoleLevel: derives the user's base role per org (or per project for project-invited members) from the ungated /platform/profile/ permissions rows via four discriminating ABAC probes. Works for every member type with no permission-gated endpoint. - computeTokenRoleContext + applySelectionToRoleContext: role resolution (expensive, memoized) is split from selection evaluation (cheap, re-run per permission toggle). AccessToken.permissions.ts gains only what the roles module needs: the PermissionLevel type and the catalog's `level` field (decides whether an org or project role governs a resource), plus getEntryScopes, which selectionToScopes now reuses. The UI-only additions from #48742 (risk badge/dot variants, mode labels, the OverallRisk.text -> description rename) are deliberately left out so this PR touches no .tsx. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added role-aware evaluation for scoped access-token permissions. * Added support for organization- and project-level permission scoping. * Added guidance when selected permissions exceed the current role, including read-only downgrades and inaccessible resources. * Added clearer grouping of permission access issues by resource. * **Tests** * Added comprehensive coverage for role mapping, permission evaluation, scoping, and failure scenarios. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Co-authored-by: Wen Bo Xie <wenbox323@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
33008a39e5 |
chore(studio): remove scoped pat orphaned form (#48803)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? First step in breaking down #48635 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Removed the scoped access-token form, including token details, expiration settings, resource access, and permission configuration. * Removed resource and permission selection controls from the access-token workflow. * **Tests** * Removed automated coverage for access-token validation, permission handling, expiration logic, and resource selection. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Wen Bo Xie <wenbox323@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
1ff84a239c |
docs(auth): note that resetPasswordForEmail doesn't send email for un… (#48800)
add note on `resetPasswordForEmail` doesn't send email for unregistered emails <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified that password reset requests do not reveal whether an email address is associated with an account. * Documented that requests for unrecognized email addresses complete without an error. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Jeremias Menichelli <jmenichelli@gmail.com> |
||
|
|
cddb430310 |
feat(studio): scoped pat root branch (#48384)
## Description This is the Scoped PAT stacked PRs root branch ## How to test ### With the `scopedPAT` enabled (default on staging) Go to https://studio-staging-git-scopedpat-merge-token-lists-supabase.vercel.app/dashboard/account/tokens. - You shouldn't see two tabs anymore - If you had classic tokens, they should have the _Legacy_ badge - You can create scoped tokens - You have a way to copy newly created tokens before closing the form side panel ### With the `scopedPAT` disabled (use the devtool to override) - You shouldn't see two tabs anymore - If you had classic tokens, they should **not** have the _Legacy_ badge - You can create classic tokens - You have a way to copy newly created tokens above the list upon form submission <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Show classic and scoped access tokens together in one list, with classic tokens labeled “Legacy” when the scoped experience is enabled. * Add scoped access token creation with a two-step configure → review → success flow (when enabled). * Add a dismissible migration notice about scoped tokens with a link to API docs. * Show “View permissions” only for scoped tokens. * **Bug Fixes** * Token deletion now supports both classic and scoped tokens with the correct confirmation and success handling. * The scoped tokens page now redirects to the unified access tokens page. * **Accessibility** * Improved accessibility by adding a label to the token “more options” action. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Ali Waseem <waseema393@gmail.com> Co-authored-by: kemal.earth <606977+kemaldotearth@users.noreply.github.com> |
||
|
|
2afb87af05 |
fix(ui): add bottom padding to scroll container in RLS search (#48759)
Fixes FE-4075. ## What kind of change does this PR introduce? The footer displaying the total number of RLS policies overlaps the last search result in the RLS Policy Search dialog. As a result, the last policy entry is partially hidden and cannot be fully read when scrolling to the bottom. ## What is the current behavior? The search results container now reserves space for the footer, preventing it from overlapping the last search result. All policy entries remain fully visible when scrolling to the bottom. <img width="400" height="300" alt="image" src="https://github.com/user-attachments/assets/46529ca4-bdce-4fa2-b0ba-ea87e769cc24" /> ## What is the new behavior? <img width="400" height="300" alt="CleanShot 2026-08-05 at 18 19 27@2x" src="https://github.com/user-attachments/assets/093a3f9e-fd4c-4ff6-b483-2839f3916d13" /> ## How to test - Open a project in the Supabase Dashboard. - Navigate to Database → RLS Policies. - Open the policy search dialog. - Search for a term that returns enough results to make the list scrollable - Scroll to the bottom of the results. The [database.sql](https://gist.github.com/monicakh/49b5ff201893eb43aea329395b3f635b) to create the tables/policies to test. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved scrolling in policy search results. * Added spacing at the bottom so results remain visible above the fixed footer. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
840127cd69 |
let inline error callers own mutation failures (#48640)
## What kind of change does this PR introduce? Code clean-up following #48470, #48471, #48472, #48473, and #48474. ## What is the current behavior? Mutation hooks provide fallback error toasts, so callers that already render errors inline must suppress those toasts with empty `onError` handlers. ## What is the new behavior? The affected callers own their error presentation. Inline interstitial errors remain unchanged, API authorisation retains its state-reset handlers, and Project Claim retains its combined caller-owned toast. ## To test There is no useful before-and-after visual check for this PR: the rendered error states should be identical on `master` and this branch. The change only removes the default-toast and no-op-handler pair underneath the UI. The existing [Organisation Invite](https://github.com/supabase/supabase/pull/48470), [API authorisation, AWS Marketplace](https://github.com/supabase/supabase/pull/48471), and [Stripe Projects](https://github.com/supabase/supabase/pull/48472) failure tests cover the inline errors and confirm that no duplicate toast appears. |
||
|
|
93b5ae71bf |
chore: remove unused useProjectUsageStats hook (#48792)
## Problem `useProjectUsageStats` (`apps/studio/hooks/analytics/useProjectUsageStats.tsx`) has no importers anywhere in the codebase — dead code, and it also still queries BigQuery directly (`logs.all`, no OTEL path), which would've made it another gap in the reports→ClickHouse migration if it were ever wired up. ## Fix Deletes the file. Confirmed nothing imports it, and none of its own imports (`useFillTimeseriesSorted`, `useTimeseriesUnixToIso`, `genChartQuery`, `EventChart`) become unused as a result — all are still used elsewhere. ## How to test - `pnpm tsc --noEmit` — no errors referencing the removed file. - `pnpm vitest run hooks/analytics` — 28 tests pass, no breakage. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Removed the project usage analytics statistics feature, including its data retrieval, time-series processing, filtering, refresh controls, and loading/error states. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8618991b6f |
Initialize explorer home page (#48790)
## Context More groundwork for the Explorer - initializing the home page Note that nothing here is functional, all just visual still <img width="1387" height="960" alt="image" src="https://github.com/user-attachments/assets/d4967578-edbd-476f-8150-d9d5e9d66666" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a new Explorer landing page with an assistant chat form. * Added quick actions for creating notebooks and SQL work. * Added notebook and chat template cards for faster project exploration. * **Improvements** * Explorer content now fills the available page height. * Assistant send button styling now reflects whether submission is available. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
21919ec9b8 | feat(pipelines): Use new restart endpoint (#48737) | ||
|
|
51c5b9f013 |
chore: sync ssl enforcement and temporary access (#48743)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Chore - fix-up ## What is the current behavior? Temporary access depends on ssl enforcement. The frontend doesn't enforce this very well or keep state between the two configs. ## What is the new behavior? This updates the two configs to be interdependent and updates to each one triggers a frontend state change on the other. ## Additional context Before: https://github.com/user-attachments/assets/8f040b62-587c-4268-9e27-27dd09b052a3 After: https://github.com/user-attachments/assets/c62e006e-6147-4c94-b6cf-375ca300b890 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added confirmation dialogs and downtime warnings before changing database SSL enforcement. - Added loading states and success or failure notifications for SSL updates. - Enabled SSL enforcement directly from temporary database access settings. - **Bug Fixes** - Prevented SSL enforcement from being disabled while temporary database access is enabled. - Improved settings refresh after SSL enforcement changes. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4550ee18a4 |
Initialize tabs UI for explorer (#48789)
## Context Continued ground work for Explorer - just initializes the Tab UI for Explorer as such: - Plan is to continue using the existing tabs store + EditorTabs component - Purely visual, nothing functional <img width="1389" height="556" alt="image" src="https://github.com/user-attachments/assets/d46c5ae7-01a8-4887-9452-11b98327d6bf" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added an Explorer workspace with animated navigation and tab controls. * Added a home tab and a new-tab menu for creating notebooks, with chat creation shown as unavailable. * Added support for notebook tabs in the editor and Explorer navigation. * Added flexible tab layouts with custom tab content, optional new-tab actions, and configurable collapse controls. * Improved editor navigation to recognize Explorer workspaces alongside existing table and SQL editors. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a18ee934cd |
docs(auth): handle incoming deep link URLs on Swift (#48774)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update. ## What is the current behavior? The Swift tab in the [Native Mobile Deep Linking guide](https://supabase.com/docs/guides/auth/native-mobile-deep-linking?platform=swift) only covers registering a custom URL scheme (Info.plist config). Unlike the React Native, Flutter, and Kotlin tabs, it never shows the runtime code that actually consumes the incoming URL and completes the sign-in, so a Swift developer following the guide is left without a working implementation. Linear: [SDK-83](https://linear.app/supabase/issue/SDK-83/swift-improve-docs-on-how-to-handle-deep-link-url) ## What is the new behavior? Added a "Handling the incoming URL" section to the Swift tab with: - SwiftUI: `onOpenURL` calling `supabase.auth.handle(url)` - UIKit app delegate lifecycle: `application(_:didFinishLaunchingWithOptions:)` and `application(_:open:options:)` - UIKit scene delegate lifecycle: `scene(_:openURLContexts:)` - A note pointing to `session(from:)` for callers that need the returned `Session` or custom error handling `handle(url)` and its usage patterns match the current `supabase-swift` reference spec (`supabase_swift_v2.yml`) and source. Also added `UIKit` to the docs spelling allowlist (`supa-mdx-lint/Rule003Spelling.toml`) since it isn't in the dictionary. ## Additional context `pnpm lint:mdx` passes on the changed file. `pnpm build:guides-markdown` fails, but on a pre-existing unrelated issue (missing generated `database-advisors.json`), not on this change. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Swift guidance for handling authentication deep links in SwiftUI and UIKit apps. * Documented deep-link behavior during cold launches and scene-based URL delivery. * Clarified when to use `handle(_:)` and `session(from:)`, including error-handling considerations. * Updated the SwiftUI tutorial to pass authentication URLs directly to the recommended handler. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
a7671019a8 |
Scaffold the explorer layout (#48740)
## Context Resolves FE-4074 Just adds scaffolding for the explorer UI - no data fetching yet. Initializes the page + side nav, based off Saxon's POC in `poc/explorer-prototype` <img width="1389" height="500" alt="image" src="https://github.com/user-attachments/assets/8f293992-97d9-403e-91d6-2e104cd20eb5" /> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## New Features - Added a project Explorer page accessible from `/project/:ref/explorer`. - Added navigation for browsing notebooks and chats. - Added search fields, back navigation, animated transitions, and empty states for Explorer sections. - Added a conditional Explorer link to the SQL Editor menu when enabled. ## Documentation - Marked the Explorer route migration as complete in the migration checklist. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
ec24d69369 |
Browser compatibility for colours (#47801)
Replaces abs and from for foreground colours to potentially improve browser compatibility <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Style** * Improved semantic color calculations for broader browser compatibility. * Refined foreground, muted, and tertiary text colors for more consistent theme rendering. * Improved surface overlay contrast across different tones. * Fine-tuned the light theme’s link color brightness for better visual balance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Danny White <3104761+dnywh@users.noreply.github.com> |
||
|
|
e0cc680653 |
feat(www): update Partner Day at Select 2026 go page copy (#48778)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content update (marketing copy) for the `www` app. ## What is the current behavior? `/go/select-2026/partner-day` copy is a couple of revisions behind the latest Notion draft (see #48771 and #48773 for prior rounds). ## What is the new behavior? Updates the page copy to match the newest draft. ## Additional context - Verified locally in the browser against the Notion copy doc, word-for-word. - `prettier --check` passes on the changed file. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Content Updates** * Clarified Partner Day event details, including the day-before-Select note. * Improved venue information messaging. * Updated the RSVP question to reference Select on October 2 and the Partner Day invitation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
d61d3533f2 |
docs: fix broken Swift example in joins-and-nesting guide (#48775)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs fix. ## What is the current behavior? Fixes [SDK-958](https://linear.app/supabase/issue/SDK-958/docs-incomplete-documentation), reported via the docs feedback widget on [joins-and-nesting](https://supabase.com/docs/guides/database/joins-and-nesting). In the "Specifying the `ON` clause for joins with multiple foreign keys" section, the Swift example was broken relative to the other language tabs (JS, Dart, Kotlin, Python, C#): - The query string aliased the second embed as `scans: scan_id_end`, which isn't valid PostgREST embed syntax (should be `end_scan:scans!scan_id_end`). - The `Shift` struct only declared a single `scans: [Scan]` property with no `CodingKeys` entry for `start_scan` or `end_scan` — so it never actually decoded either aliased relation, which is why the reporter couldn't tell where `start_scan` was supposed to come from. ## What is the new behavior? - Query now aliases both relations consistently: `start_scan:scans!scan_id_start (...)` and `end_scan:scans!scan_id_end (...)`, matching the other language examples. - `Shift` struct now declares `startScan: Scan` and `endScan: Scan`, mapped via `CodingKeys` to `start_scan` and `end_scan`. ## Additional context Docs-only change to a code sample inside `apps/docs/content/guides/database/joins-and-nesting.mdx`. Verified with `prettier --check` (mdx lint tool failed locally due to an unrelated missing native module, `node-pty`). <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Updated the Swift join example to represent separate start and end scan relationships. * Revised response field selections and coding keys to match the updated relationship names. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
6b1fc3d11d |
recover failed Vercel deploy connections (#48474)
## What kind of change does this PR introduce? Bug fix. ## What is the current behavior? A failed Vercel connection after project creation is only logged, leaving the project-creation screen in its loading state. ## What is the new behavior? The flow preserves the created project and shows the connection error with retry and open-project actions in the standard project-creation footer. Project-creation failures remain ordinary inline form errors. Connection failures are owned by this flow without a duplicate toast or a no-op error handler. | Before | After | | --- | --- | |  | <img width="1024" height="563" alt="Create Vercel Project Supabase" src="https://github.com/user-attachments/assets/b7d3fdca-d7a0-4b50-9231-3cf7dc371a87" /> | ## To test ### Before on master 1. Switch to `master`. 2. With local Studio running and while signed in, open an organisation you can access. Copy its slug from `http://localhost:8082/org/<YOUR_ORG_SLUG>`. 3. Open `apps/studio/components/interfaces/ProjectCreation/ProjectCreationForm.tsx`. 4. Find `isSuccessNewProject={isSuccessNewProject}` in the `ProjectCreationFooter` props and temporarily change it to: ```tsx isSuccessNewProject={true} ``` 5. Replace `<YOUR_ORG_SLUG>` in this URL with the slug from step 2, then open it: `http://localhost:8082/integrations/vercel/<YOUR_ORG_SLUG>/deploy-button/new-project`. 6. Confirm **Create new project** remains in its loading state and there is no error, retry action, or route to the created project. This represents the current stuck state. 7. Revert the temporary edit before switching branches. ### After on this branch 1. Switch to `dnywh/vercel-deploy-recovery`. 2. With local Studio running and while signed in, open an organisation you can access. Copy its slug from `http://localhost:8082/org/<YOUR_ORG_SLUG>`. 3. Open `apps/studio/pages/integrations/vercel/[slug]/deploy-button/new-project.tsx`. 4. Find the conditional beginning with `newProjectRef === undefined` inside `InterstitialLayout`. 5. Replace that whole conditional with: ```tsx <VercelConnectionError projectRef="abcdefghijklmnopqrst" message="Connection request failed" onRetry={() => undefined} /> ``` 6. Replace `<YOUR_ORG_SLUG>` in this URL with the slug from step 2, then open it: `http://localhost:8082/integrations/vercel/<YOUR_ORG_SLUG>/deploy-button/new-project`. 7. Confirm the admonition says **Unable to connect to Vercel** and **Your Supabase project was still created. Error: Connection request failed**. 8. Confirm **Open project** and **Retry connection** appear as compact, right-aligned footer buttons. The retry action is intentionally inert in this visual-only mock, and no project or Vercel connection is created. 9. Revert the temporary edit. ## Additional context Follows #48473. The consistency follow-up #48640 is stacked on this PR. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added inline error messages to project creation forms for integration, API, and validation failures. - Added clear Vercel connection states, including waiting, connecting, success, and error screens. - Added retry actions and links to open successfully created projects. - **Bug Fixes** - Improved error handling so Vercel connection issues remain visible in context instead of appearing only as notifications. - **Tests** - Added coverage for partial-success messaging, project links, and retry behavior. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Joshen Lim <joshenlimek@gmail.com> |
||
|
|
801ef21ce6 |
Add Matt Smiley to humans.txt (#48729)
Add myself (Matt Smiley) to humans.txt as part of onboarding to Supabase. ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update to add new joiner (me) ## What is the current behavior? NA ## What is the new behavior? Adds new team member ## Additional context Part of my onboarding process <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added Matt Smiley to the team member list in the project credits. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
8d1ff7d38f |
feat(www): update Partner Day at Select 2026 go page copy (#48773)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content update (marketing copy) for the `www` app. ## What is the current behavior? `/go/select-2026/partner-day` copy is one revision behind the latest draft (see #48771 for the prior round). ## What is the new behavior? Updates the page copy to match the newest Notion draft. ## Additional context - Verified locally in the browser against the Notion copy doc, word-for-word. - Verified the RSVP form's "Are you attending Select 2026?" select field opens, selects, and submits correctly. - `prettier --check` passes on the changed file. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Content Updates** - Refined Partner Day event messaging and “What to expect” descriptions. - Simplified the hero description by removing timing-specific wording. - Shortened inaugural-event messaging for clearer, more concise communication. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
2736abf4c7 |
feat(www): update Partner Day at Select 2026 go page copy (#48771)
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Content update (marketing copy) for the `www` app. ## What is the current behavior? `/go/select-2026/partner-day` has stale copy from an earlier draft of the event: a time-boxed agenda table and a "What you'll gain" feature grid that no longer match the approved messaging. ## What is the new behavior? Updated copy! :) ## Additional context - Verified the RSVP form's "Are you attending Select 2026?" select field opens, selects, and submits correctly, with no React hydration warnings on a clean `.next` build. - `pnpm --filter=www exec tsc --noEmit` and `prettier --check` both pass on the changed file. - `pnpm build --filter=www` fails locally, but this is pre-existing and unrelated to this change — it requires a `DOCS_GITHUB_APP_PRIVATE_KEY` secret (for the `docs` app's federated-content prebuild step) that isn't available in this local environment. Confirmed the identical failure occurs on `master` with no changes applied. |